Risk Manager

ServiceNowChicago, IL
12h

About The Position

As the Risk Manager on the Digital Technology GRC team, you will play a central role in advancing our federal compliance posture and GRC program maturity. You will guide initiatives related to CMMC (Cybersecurity Maturity Model Certification) Level 2 readiness, NIST framework implementation, and enterprise-wide risk assessment across infrastructure, endpoints, identity, cloud, and data protection domains. You will partner closely with Security Architecture, IT Operations, SecOps, Internal Audit, Legal & Compliance, and Executives to assess risk, implement controls, and ensure our organization meets the rigorous standards required for federal contracting. You will drive compliance and risk management across key areas such as: CMMC 2.0 Level 2 Assessment Readiness & Certification NIST SP 800-171 / NIST CSF Control Mapping & Implementation Enterprise Risk Assessment & Remediation Planning System Security Plans (SSP) & Plan of Action & Milestones (POA&M) GRC Process Maturity & Automation Federal Compliance Documentation & Evidence Management This is a high-impact, high-visibility role designed for someone who combines deep knowledge of federal cybersecurity frameworks with the ability to translate technical compliance requirements into actionable plans and executive-ready communications.

Requirements

  • 7–8 years of experience in cybersecurity, information security, GRC, or federal compliance roles.
  • Deep working knowledge of CMMC 2.0, NIST SP 800-171, NIST SP 800-53, and NIST Cybersecurity Framework (CSF).
  • Hands-on experience leading or supporting CMMC assessments, including application scoping, control mapping, gap analysis, and remediation planning.
  • Strong understanding of federal contracting compliance requirements, including DFARS 252.204-7012 and CUI (Controlled Unclassified Information) handling.
  • Experience developing and maintaining SSPs, POA&Ms, and compliance documentation for federal authorization.
  • Proven ability to conduct risk assessments across enterprise environments covering endpoints, identity, cloud, and data protection.
  • Working knowledge of the ServiceNow platform, including familiarity with IRM, SecOps, CMDB, or ITSM modules for managing security and compliance workflows.
  • Excellent written and verbal communication skills with demonstrated ability to present technical findings to executive audiences.
  • Experience working cross-functionally with IT, security, audit, and legal teams in a large enterprise environment.

Nice To Haves

  • Professional certifications such as CISSP, CISM, CISA, CAP (Certified Authorization Professional), or CMMC Registered Practitioner (RP).
  • Hands-on experience with ServiceNow IRM (Integrated Risk Management), including Risk Management, Policy & Compliance Management, Audit Management, and Vendor Risk Management modules.
  • Experience with broader ServiceNow platform capabilities including CMDB/APM, SecOps (Security Incident Response, Vulnerability Response), ITSM, and IT Asset Management for integrated security and compliance workflows.
  • Familiarity with ServiceNow reporting, dashboards, Performance Analytics, and workflow automation to drive GRC program efficiency and executive visibility.
  • Familiarity with FedRAMP, FISMA, FIPS 140-2/3 encryption requirements, and DoD cybersecurity policies.
  • Background in evaluating dual-environment architectures (e.g., O365 commercial vs. GCC High) for compliance alignment.
  • Experience with SIEM, EDR (e.g., CrowdStrike), vulnerability management tools, and security architecture review processes.
  • Knowledge of identity and access management frameworks, including Okta, Active Directory, and SailPoint integrations.
  • Prior experience in enterprise-scale assessment campaigns involving 50+ applications or business units.
  • Experience in building or consuming continuous monitoring, control hygiene, or AI-enabled risk/issue automation workflows (e.g., automated control testing, continuous controls monitoring, risk scoring, AI/ML-driven issue remediation).

Responsibilities

  • Risk Assessment & Management Conduct comprehensive risk assessments across infrastructure, endpoints, identity management, data protection, and cloud environments.
  • Identify, document, and track security gaps and remediation activities in the enterprise risk register.
  • Perform control effectiveness testing and support continuous monitoring initiatives to ensure ongoing compliance posture.
  • Cross-Functional Collaboration & Communication Partner with Security Architecture, IT Operations, SecOps, Internal Audit, and Legal & Compliance to align security controls and risk mitigation strategies.
  • Translate complex technical findings and compliance status into executive-ready reports, dashboards, and briefings for senior principals.
  • Act as a subject matter expert for CMMC and NIST compliance across the organization, providing guidance and training to stakeholders.
  • GRC Program & Process Maturity Support the development and maturation of GRC processes, including policy management, control mapping, audit support, and evidence management workflows.
  • Evaluate and recommend GRC tooling and automation opportunities to increase efficiency and accuracy of compliance operations.
  • Contribute to enterprise-wide assessment campaigns and support regulatory change management activities.
  • ServiceNow Platform & GRC Tooling Leverage ServiceNow IRM (Integrated Risk Management) modules — including Risk Management, Policy & Compliance Management, Audit Management, and Vendor Risk Management — to manage and operationalize compliance workflows.
  • Utilize ServiceNow SecOps (Security Incident Response, Vulnerability Response), CMDB/APM, ITSM, and IT Asset Management to support integrated security and compliance operations.
  • Build and maintain GRC dashboards, reports, and Performance Data views to provide executive visibility into risk posture, control coverage, and compliance status.
  • Drive workflow automation within the ServiceNow platform to streamline evidence collection, control testing, risk scoring, and remediation tracking.

Benefits

  • health plans, including flexible spending accounts
  • a 401(k) Plan with company match
  • ESPP
  • matching donations
  • a flexible time away plan
  • family leave programs

Stand Out From the Crowd

Upload your resume and get instant feedback on how well it matches this job.

Upload and Match Resume

What This Job Offers

Job Type

Full-time

Career Level

Mid Level

Education Level

No Education Listed

Number of Employees

5,001-10,000 employees

© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service